{"id":29235,"date":"2026-05-06T09:45:12","date_gmt":"2026-05-06T09:45:12","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/29235\/"},"modified":"2026-05-06T09:45:12","modified_gmt":"2026-05-06T09:45:12","slug":"shadow-ai-why-boards-are-failing-the-governance-test","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/29235\/","title":{"rendered":"Shadow AI: Why Boards Are Failing the Governance Test"},"content":{"rendered":"<p>Shadow AI \u2013 the unsanctioned use of artificial intelligence tools by employees without organisational policy, oversight, or formal approval \u2013 has become one of the defining governance failures in enterprise technology today.<\/p>\n<p>As <a href=\"https:\/\/www.cxtoday.com\/security-privacy-compliance\/vercels-breach-is-a-warning-shadow-ai-risks-to-cx-are-escalating\/\" rel=\"nofollow noopener\" target=\"_blank\">Vercel\u2019s recent breach<\/a> makes clear, the consequences reach well beyond an IT department\u2019s inbox. Customer data, intellectual property, and hard-won regulatory standing are all in play. And with <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/regulatory-framework-ai\" rel=\"nofollow noopener\" target=\"_blank\">EU AI Act<\/a> enforcement arriving in August 2026, the window to get ahead of this risk is closing faster than most boards realise.<\/p>\n<p>What Is Shadow AI, and How Did It Become an Enterprise Problem?<\/p>\n<p>The term will be familiar to anyone who spent the 2010s arguing with employees about personal Dropbox accounts and WhatsApp groups. Shadow IT \u2013 the use of unsanctioned software to fill gaps left by corporate tooling \u2013 costs organisations millions in data exposure and regulatory fines before boards eventually catch up. The pattern is repeating. The difference this time is scale, speed, and sensitivity.<\/p>\n<p>AI tools are more capable, more personally compelling, and more deeply embedded in daily workflows than a shared spreadsheet ever was. The data employees feed into them \u2013 customer transcripts, product roadmaps, deal intelligence, HR records \u2013 is often far more valuable and legally protected than anything that passed through a rogue Dropbox folder.<\/p>\n<p>We sat down with Gary Hibberd, Head of <a href=\"https:\/\/www.consultantslikeus.co.uk\/\" rel=\"nofollow noopener\" target=\"_blank\">Consultants Like Us<\/a>, to get his perspective:<\/p>\n<p>\u00a0\u201cWe are trying to implement AI on top of data chaos. A lot of organisations don\u2019t really understand their current platforms.\u201d<\/p>\n<p>Before shadow AI can be governed, many organisations first need a clearer picture of what data they hold \u2013 and where it already lives.<\/p>\n<p>Does the Board Understand the Risk Shadow AI Poses?<\/p>\n<p>In a word: no. And Hibberd does not soften the assessment.<\/p>\n<p>\u201cFor most people, AI has only been around since 2022,\u201d he says. The mental model most boards are working from is that of a conversational search tool. The reality \u2013 AI embedded in CRM platforms, customer service workflows, contact center infrastructure, and employee productivity suites \u2013 is categorically different, and the risk exposure that comes with it is orders of magnitude larger.<\/p>\n<p>\u201cOne of the biggest risks the board is facing is shadow AI,\u201d Hibberd says. \u201cPeople are using it in the workspace without any real guardrails \u2013 policies, procedures, training, explaining to people about not putting confidential data into AI. That could be personal data, but it could also be the intellectual property of the company.\u201d<\/p>\n<p>A <a href=\"https:\/\/www.ey.com\/en_gl\/newsroom\/2025\/10\/ey-survey-companies-advancing-responsible-ai-governance-linked-to-better-business-outcomes\" rel=\"nofollow noopener\" target=\"_blank\">recent EY survey<\/a> found that 99% of organisations surveyed had experienced financial losses from AI-related risks, with compliance failures, flawed outputs, and data exposure among the most common causes. Estimated combined losses across surveyed firms reached $4.4 billion.<\/p>\n<p>Is Shadow AI a Security Failure \u2013 or a Leadership One?<\/p>\n<p>This is the reframe most organisations are still missing. Shadow AI is not, at its root, a discipline problem. It is a clarity problem \u2013 and that makes it a leadership responsibility.<\/p>\n<p>\u201cAI offers lots of opportunities to get quicker and better at what we do,\u201d Hibberd says. \u201cSo people are using it indiscriminately in their organisations without any real forethought about what they\u2019re using it for.\u201d Employees are not acting recklessly; they are responding rationally to capable tools, competitive pressure, and an organisational vacuum where policy should be.<\/p>\n<p>Hibberd describes this as \u201cadoption without clarity.\u201d Organisations have not defined what AI is actually for \u2013 so individuals do it themselves. Without those answers at the leadership level, individuals fill the vacuum themselves \u2013 and the results increasingly land in boardroom risk registers and regulatory investigations.<\/p>\n<p>\u201cNone of it\u2019s technical,\u201d Hibberd says of the governance conversation. \u201cIt\u2019s business. Security is not an IT risk; it\u2019s a business risk.\u201d<\/p>\n<p>How Should Organisations Respond to Shadow AI?<\/p>\n<p>The instinct is to reach for tools \u2013 an AI governance platform, a usage monitoring solution, a vendor agreement. Hibberd\u2019s prescription is to start with the fundamentals:<\/p>\n<p>\u201cMy first suggestion would be to look at the <a href=\"https:\/\/digital-strategy.ec.europa.eu\/en\/policies\/regulatory-framework-ai\" rel=\"nofollow noopener\" target=\"_blank\">EU AI Act<\/a>,\u201d he says. \u201cWe need to think about being fair, transparent, and effective, which are the act\u2019s core principles.\u201d Rather than framing compliance as a legal department exercise, he argues that those three principles offer a practical governance lens that any business leader can engage with, regardless of technical fluency.<\/p>\n<p>The next step is accountability of ownership:<\/p>\n<p>\u201cYou need someone in your organisation who is looking at the broader context of AI \u2013 looking at the effectiveness, the fairness, and the transparency of the tools, and then looking at simple security principles: governance, risk, and compliance.\u201d<\/p>\n<p>Standards frameworks such as <a href=\"https:\/\/www.iso.org\/standard\/81230.html\" rel=\"nofollow noopener\" target=\"_blank\">ISO\/IEC 42001<\/a> \u2013 published in December 2023 as the world\u2019s first international AI management system standard \u2013 provide a structured, auditable route to doing precisely this and are increasingly referenced in enterprise procurement as the AI equivalent of ISO 27001 for information security.<\/p>\n<p><a href=\"https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2022-12-14-gartner-identifies-top-trends-in-data-and-analytics-f\" rel=\"nofollow noopener\" target=\"_blank\">Gartner projects<\/a> that by 2026, 50% of governments worldwide will enforce responsible AI through binding regulations \u2013 making a documented, repeatable governance framework no longer optional for vendors operating at scale.<\/p>\n<p>The return on getting the basics right, Hibberd argues, is substantial:<\/p>\n<p>\u201cUnderstand the basics, understand the foundations, and you\u2019ll quickly find that you\u2019re going to satisfy 70, if not 80% of any issues that you\u2019ve come across.\u201d<\/p>\n<p>The boards that treat shadow AI as a symptom of strategic ambiguity \u2013 rather than a problem to be policed \u2013 will build governance frameworks that hold. The tools are not going away.<\/p>\n<p>Employee appetite is not going away. And with regulatory enforcement timelines now measured in months, organisations still waiting for a definitive internal policy before acting are already behind.<\/p>\n<p>The only question left is whether leadership has decided what to do \u2013 or whether employees will decide for them.<\/p>\n<p>FAQsWhat is shadow AI?<\/p>\n<p>Shadow AI refers to the use of artificial intelligence tools by employees without formal organisational approval, policy, or oversight.<\/p>\n<p>Why is shadow AI a risk for businesses?<\/p>\n<p>Employees using unsanctioned AI tools can inadvertently expose sensitive customer data, company intellectual property, and personally identifiable information to third-party platforms outside the organisation\u2019s control.<\/p>\n<p>How is shadow AI different from shadow IT?<\/p>\n<p>Shadow AI carries greater risk than traditional shadow IT because the data employees feed into AI tools \u2013 customer transcripts, financial records, strategic plans \u2013 is typically far more sensitive than files shared through an unapproved cloud drive.<\/p>\n<p>What should organisations do to address shadow AI?<\/p>\n<p>Organisations should start by defining clear AI objectives, appointing a cross-functional governance lead, and grounding policy in the core principles of the EU AI Act: fairness, transparency, and effectiveness.<\/p>\n<p>Does the EU AI Act cover shadow AI?<\/p>\n<p>The EU AI Act does not target shadow AI directly, but its compliance obligations \u2013 particularly around high-risk AI systems and accountability frameworks \u2013 apply regardless of whether tools were formally sanctioned at organizational level.<\/p>\n","protected":false},"excerpt":{"rendered":"Shadow AI \u2013 the unsanctioned use of artificial intelligence tools by employees without organisational policy, oversight, or formal&hellip;\n","protected":false},"author":2,"featured_media":29236,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[2],"tags":[24,25,6314,19178,1681],"class_list":["post-29235","post","type-post","status-publish","format-standard","has-post-thumbnail","category-ai","tag-ai","tag-artificial-intelligence","tag-cybersecurity-for-cx","tag-gdpr-ccpa-compliance","tag-security-and-compliance"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/29235","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=29235"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/29235\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/29236"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=29235"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=29235"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=29235"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}